CVE-2025-66675
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-16
Assigner: Apache Software Foundation
Description
Description
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
It's related toΒ https://cve.org/CVERecord?id=CVE-2025-64775 Β - this CVE addresses missing affected version 6.7.4
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | struts | From 2.0.0 (inc) to 2.3.37 (inc) |
| apache | struts | From 2.5.0 (inc) to 2.5.33 (inc) |
| apache | struts | From 6.0.0 (inc) to 6.8.0 (exc) |
| apache | struts | From 7.0.0 (inc) to 7.1.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-459 | The product does not properly "clean up" and remove temporary or supporting resources after they have been used. |